insecure-source-code-management

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent as a penetration-testing guide, but it equips an AI agent with offensive discovery and extraction techniques for source code and secrets. No clear malware or deceptive data routing is present, yet the capability set is high risk because it enables real exploitation and sensitive-data recovery.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Apr 9, 2026, 04:29 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Finsecure-source-code-management%2F@a7c0adca6146ee3d53421dc356540e1e9a34be91